NSX Compute Manager Connection Down Post Certificate Change
search cancel

NSX Compute Manager Connection Down Post Certificate Change

book

Article ID: 426589

calendar_today

Updated On:

Products

VMware NSX VMware Cloud Foundation

Issue/Introduction

When trying to reconnect the compute manager in NSX it shows "Error: Failed to import the trusted root certificate for compute manager <vcenter_fqdn>. Try again.

Environment

NSX 9.x 

VMware Cloud Foundation 9.x

Cause

The root certificate PKI does not have CN values for the issue field. Starting with NSX 9.0, the NSX Inventory imports the vCenter root certificate during Compute Manager (vCenter) registration and uses it for authentication during vCenter connection. Consequently, NSX now validates the Common Name (CN) to identify the vCenter root certificate.

Prior to version 9.0, NSX did not validate the CN, as it relied on the thumbprint of the vCenter SSL certificate for authentication.

Resolution

Replace the CA's root certificate with one that followed certificate RFC standards and includes a CN value. 

Workaround: 

Revert certificates to VMCA certificates.